You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何启用K8s主节点的NodePort服务路由功能?

Fix NodePort Access on Kubernetes Master Node (v1.8.6)

Let’s walk through getting your master node to route NodePort service traffic just like your slave nodes do. Here are the key checks and fixes tailored to Kubernetes v1.8.6:

1. Ensure kube-proxy is running on the master node

kube-proxy is responsible for setting up the network rules that route NodePort traffic to your pods.

  • First, check if a kube-proxy pod is running on your master:
    kubectl get pods -n kube-system | grep kube-proxy
    
  • If there’s no kube-proxy pod for your master, check the kube-proxy DaemonSet configuration—sometimes it’s set to only run on worker nodes:
    kubectl get daemonset kube-proxy -n kube-system -o yaml | grep -A 5 nodeSelector
    
    • If you see a nodeSelector that excludes master nodes (like node-role.kubernetes.io/node: ""), either remove that selector from the DaemonSet, or add the required label to your master node:
      kubectl label node <your-master-node-name> node-role.kubernetes.io/node=true
      
    • After making changes, the DaemonSet will automatically spawn a kube-proxy pod on the master.

2. Verify iptables rules and IP forwarding

Kubernetes uses iptables to route NodePort traffic. Let’s make sure the rules are in place:

  • On your master node, check for the specific NodePort rule (replace 30141 with your service’s NodePort):
    iptables-save | grep 30141
    
  • If you don’t see any rules for that port, restart the kube-proxy pod to regenerate them:
    kubectl delete pod <kube-proxy-pod-name> -n kube-system
    
  • Also, ensure IP forwarding is enabled on the master—this is required for traffic routing:
    sysctl net.ipv4.ip_forward
    
    • If the output is net.ipv4.ip_forward = 0, enable it temporarily:
      sysctl -w net.ipv4.ip_forward=1
      
    • To make this permanent, add net.ipv4.ip_forward=1 to /etc/sysctl.conf and run sysctl -p.

3. Check firewall/security group settings

Even if the Kubernetes rules are correct, your master node’s firewall or cloud security group might be blocking NodePort traffic:

  • For Linux firewalls (like ufw or firewalld), allow the NodePort range (default is 30000-32767) and your service’s target port (e.g., 5601 for Kibana):
    • For ufw:
      ufw allow 30000:32767/tcp
      ufw allow 5601/tcp
      
    • For firewalld:
      firewall-cmd --add-port=30000-32767/tcp --permanent
      firewall-cmd --add-port=5601/tcp --permanent
      firewall-cmd --reload
      
  • If you’re using a cloud provider, update your master node’s security group to allow inbound traffic on the NodePort (30141 in your example) from your desired source IPs.

4. Confirm kube-proxy's operating mode

In v1.8.6, kube-proxy can run in iptables or userspace mode. userspace mode is less reliable for NodePort routing, so we want to ensure it’s using iptables:

  • Check the kube-proxy ConfigMap:
    kubectl get configmap kube-proxy -n kube-system -o yaml
    
  • Look for the mode field in the config.conf section. If it’s set to userspace, update the ConfigMap to use iptables instead, then restart all kube-proxy pods:
    kubectl delete pods -n kube-system -l k8s-app=kube-proxy
    

After going through these steps, your master node should be able to route traffic to NodePort services just like your slave nodes do.

内容的提问来源于stack exchange,提问作者Silk0vsky

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 07:48:02